Business Email Compromise (BEC) / CEO Fraud
BEC / CEO fraud tricks employees into urgent wire transfers by spoofing executive email. It caused $2.9B in losses in 2023 — the #1 cybercrime threat.
What Is This Threat?
Business Email Compromise (BEC) is a sophisticated scam targeting companies that regularly perform wire transfers. Attackers either compromise a real executive's email account or spoof it convincingly, then instruct employees in finance or HR to send money to fraudulent accounts — all under the guise of an urgent, confidential business need.
The FBI IC3's 2023 report ranked BEC as the #1 cybercrime by total financial loss, with $2.9 billion stolen from businesses globally. In Europe, ENISA identifies it as a top-priority threat for organizations of all sizes.
How It Works
Variant 1 — CEO Wire Transfer Fraud:
Variant 2 — Fake Invoice Fraud:
Attackers compromise a supplier's email, wait to see an ongoing invoice thread, then send updated banking details for a legitimate pending invoice. The company pays the correct invoice amount — but to the attackers' account.
Variant 3 — Payroll Diversion:
HR receives a convincing email from an employee asking to update their direct deposit details. The next payroll goes to the attacker.
2024–2026 Evolution — Deepfake Video & Audio:
In early 2024, a Hong Kong finance worker was tricked into transferring $25 million after attending a video call with deepfake versions of his CFO and colleagues. AI-generated voice and video are now being used in BEC attacks to bypass skepticism.
Real Examples
Red Flags
company-name.net instead of company-name.com).How to Protect Yourself
- Always verify wire transfer requests or banking detail changes via a separate channel (phone call to a known number) — never rely solely on email confirmation
- Implement a two-person rule for all outgoing wire transfers above a set threshold
- Train finance and HR staff specifically on BEC patterns — attackers exploit urgency and authority
- Enable DMARC, DKIM, and SPF on your company email domain to make spoofing much harder
- Use email security tools that flag external emails impersonating internal executive names or domains
What to Do If Affected
- 1.If you suspect a fraudulent transfer was made, call your bank immediately — there is a narrow window (often under 24 hours) to attempt a recall
- 2.Report to your national cybercrime authority and FBI IC3 (ic3.gov) if in the US — swift reporting improves recovery chances
- 3.Preserve all emails, headers, and communication logs as evidence
- 4.Conduct an internal review to find how attackers obtained information (compromised inbox, LinkedIn research, supplier breach)
- 5.Notify your cyber insurance provider immediately — most BEC losses are covered only if reported within a specific timeframe